Cookie Policy

Last updated: July 23, 2026

Norveth uses a small number of cookies to keep the Service working. There is no third-party analytics or advertising tracking on this site today — if that changes, this page will be updated first.

Essential & security cookies

Strictly necessary for the Service to work — these can't be disabled without breaking sign-in.

  • __Secure-auth.session-token (auth.session-token in development): your authenticated session, set by NextAuth.
  • authjs.csrf-token: cross-site request forgery protection on sign-in.
  • A short-lived Cloudflare Turnstile token is submitted with the signup/login form to verify you're not a bot. It isn't used to track you elsewhere.

Managing cookies

Because the essential cookies above are required for authentication, rejecting them means you won't be able to stay signed in. You can still browse the marketing pages and run a sample scan without an account. Your browser's settings let you clear or block cookies at any time — check its help menu for specifics.

Updates to this policy

If Norveth adds analytics, marketing, or other non-essential cookies in the future, this page will be updated to list them before they're set.